Commit Graph
1521 Commits
Author SHA1 Message Date
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00
can1357 c55b28a26d chore(coding-agent): format eval display helpers 2026-07-24 16:49:31 +02:00
can1357 ff49b986d5 feat(coding-agent/tools): introduced language-specific code formatters for display rendering
- Added language-specific code formatters for JavaScript, Julia, Python, and Ruby to improve display rendering.
- Integrated display formatting into browser run and eval render tools while preserving verbatim execution.
- Added comprehensive test suites verifying formatting stability, lexical safety, and streaming behavior.
2026-07-24 16:26:03 +02:00
can1357 27e019981a feat(coding-agent/tools): updated bash tool prompt to list available shell builtins
- Added available shell builtins list to the bash tool prompt template.
- Added helper to check if shell builtins are disabled via settings or environment.
2026-07-24 15:02:00 +02:00
can1357 fdf921a3c4 fix(coding-agent): marked ast_edit previews as staged proposals
- Prepended a model-visible PREVIEW_PENDING_NOTICE to ast_edit preview
  results; the TUI-only proposed badge never reached the model, so
  preview diffs read as already-applied edits.
- Rendered the resolve reminder with the source tool name via
  Handlebars instead of a generic 'This is a preview'.
- Documented the xd://resolve / xd://reject two-phase flow in the
  ast_edit tool prompt.
2026-07-24 12:03:49 +02:00
can1357 d4792ed38b fix(tools): leniently inferred missing todo op from unambiguous payloads
- Kept op required in the todo schema; lenientArgValidation now routes raw args to execute(), where resolveTodoParams re-validates and repairs an omitted op (list -> init, phase+items -> append, bare items on empty list -> init).
- Ambiguous op-less calls surface the schema error as a retryable tool error instead of a hard validation failure.
2026-07-24 12:03:06 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00
can1357 024f49220e fix(coding-agent): handled xdev execution errors with mounted tool renderer
- Catch execution errors in XdevRegistry and render them using the mounted tool's error handling.
- Preserve xdev dispatch context when device execution fails.
2026-07-24 08:03:17 +02:00
can1357 4f97aea2db Merge PR #6468: fix(tools): closed spilled output descriptors on error/abort paths (@roboomp) 2026-07-24 06:51:36 +02:00
roboomp 31098f9248 fix(tools): closed spilled output descriptors on error/abort paths
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.

Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.

Fixes #6463
2026-07-24 03:44:12 +00:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357andusr-bin-roygbiv 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 0868861abd test(eval): matched allowed-agents wording in tool description 2026-07-24 02:41:35 +02:00
can1357 1e1d2e91ea style: applied biome formatting 2026-07-24 02:27:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00
can1357 0abc977d98 Merge PR #6397: fix(write): reject local read-selector-shaped write targets (@roboomp) 2026-07-24 02:24:04 +02:00
can1357 041adb2b1f fix(xdev): tolerated malformed inline-device allowlist config
Settings.get returns raw merged config without element validation, so a
scalar or non-string tools.xdevInlineDevices entry reached Bun.Glob and
threw while building the system prompt. Normalized the allowlist to
string patterns and compiled globs once per render.
2026-07-24 02:23:22 +02:00
Joe Shullandcan1357 f4641c165e feat: allowlist xdev prompt docs 2026-07-24 02:23:22 +02:00
Joe Shullandcan1357 f15191c37d feat: configure xdev prompt docs 2026-07-24 02:23:22 +02:00
can1357 3d64910bb0 feat(coding-agent/live): added realtime voice interaction with Codex Live sessions (experimental)
- Added `src/live/` subsystem with WebRTC transport, protocol parser, session controller, and headless Chromium audio injection.
- Added `LiveVisualizer` component with phase states, transcript display, and animated waveform rendering.
- Added `/live` slash command and `LiveCommandController` to toggle live voice sessions.
- Suppressed local TTS via `vocalizer.suspend()` during live mode to prevent audio conflicts.
- Added live-instructions and agent-final-message prompts for agent messaging context.
- Added `protocol.test.ts` covering event parsing, chunking, and context message construction.
2026-07-24 02:20:43 +02:00
can1357 7eeaba0471 refactor(coding-agent/session): restructured monolithic agent session
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.
2026-07-24 01:24:44 +02:00
can1357 9c44ad185c fix(read): restored untilAborted import dropped by merge overlap of #6404 and #6417
- #6417 moved findUniqueSuffixMatch (the only prior untilAborted user) out of read.ts and removed the import; #6404 added new untilAborted callsites in regions git auto-merged without conflict.
2026-07-23 22:19:37 +02:00
can1357 72ff07ff84 Merge PR #6428: fix(memory): synchronize live backend lifecycle (@roboomp) 2026-07-23 22:15:25 +02:00
can1357 2ecba08e2a Merge PR #6407: fix(browser): bound open timeout and lease browser across tab acquisition (@roboomp) 2026-07-23 22:15:24 +02:00
can1357 418076e44a fix: treat escaped quotes inside double-quoted backticks as inner quoting
Bash treats \" inside a backtick substitution nested in double quotes as
a quote delimiter for the inner command; the generic backslash-skip made
isInsideShellQuote report such quoted literals as unquoted, wrongly
expanding internal URLs inside them (Codex P2 review finding).
2026-07-23 22:15:23 +02:00
can1357 5ac3094d88 Merge PR #6418: fix(tool): expand internal urls inside backtick substitutions (@roboomp) 2026-07-23 22:15:23 +02:00
can1357 a5e59a4e56 Merge PR #6417: fix(edit): align relative path resolution (@roboomp) 2026-07-23 22:15:22 +02:00
can1357 c991270145 Merge PR #6404: fix(coding-agent): make PDF image cache content-aware (@roboomp) 2026-07-23 22:15:22 +02:00
roboomp 75668387db fix(write): guarded selector-shaped archive members
Applied the read-selector misfire check to archive members after loading
the archive entry map and before mutation. Missing empty selector-shaped
members now fail closed, while existing literal members remain writable.

Added regression coverage proving rejected writes leave archives unchanged.
2026-07-23 20:07:07 +00:00
can1357 7158dcd9b3 fix(coding-agent): deferred hub tool renderer access to avoid temporal dead zone
- Convert the hub tool renderer to a lazy getter to prevent initialization-order temporal dead zone issues.
- Add session move support to the fake ACP builtin session runtime.
2026-07-23 21:54:35 +02:00
roboomp 5a1f227a6b fix(memory): synchronized live backend lifecycle
- Serialized backend transitions across runtime state, tools, and prompts.
- Rehydrated Mnemopi listeners after clear and enqueue maintenance.
- Made memory.backend the sole post-migration local runtime gate.

Fixes #5638
2026-07-23 19:52:09 +00:00
roboomp 70e92d32a6 fix(tool): expand internal urls inside backtick substitutions
isInsideShellQuote opened an expansion context for $() command
substitution but never tracked legacy backtick substitution, so an
unquoted skill:// (or other supported scheme) nested directly inside a
backtick pair within double quotes kept the outer quote active and was
left literal. Treat an unescaped backtick as an expansion-context
boundary on the same substitution stack, restoring the outer quote when
the pair closes, matching $() behavior including nesting in either
order. Single-quoted and escaped-backtick text stay literal.

Fixes #5645
2026-07-23 19:20:08 +00:00
roboomp 662e4392da fix(edit): aligned relative path resolution
- Shared unique workspace suffix resolution between read and direct edit modes.

- Preserved create destinations and ambiguous-path failures while resolving existing update targets.

- Added direct replace, patch, and apply_patch regression coverage.

Fixes #6359
2026-07-23 19:14:09 +00:00
roboomp d4b1fd5107 fix(browser): bound open timeout and lease browser across tab acquisition
The browser tool's open action only passed the requested timeout to acquireTab; acquireBrowser ran under the caller signal alone, so CDP discovery/connect could run through its own fixed 5s/30s waits past the requested deadline. A freshly-created browser also sat in the registry at refCount 0 during worker/surface acquisition: the worker-abort branch released it only on tempHold (never on the fresh refCount-0 case), orphaning the handle, and two different-name opens sharing one refCount-0 browser let a single failure dispose it out from under the survivor.

Compose one open deadline from the caller signal and params.timeout and thread it through both acquireBrowser and acquireTab; caller cancellation stays ToolAbortError, the requested timeout becomes a timeout ToolError. Hold one explicit registry lease across tab acquisition, released exactly once on the mutually-exclusive success/rollback paths, and make the worker-abort browser release mirror the error paths' refCount-0 check.

Fixes #6365
2026-07-23 19:02:38 +00:00
roboomp 7877df00e4 fix(coding-agent): made pdf image cache content-aware
- Snapshotted source bytes before deriving path-and-content cache generations.
- Coalesced cold extraction with independent caller cancellation and atomic publication.
- Covered replacement, mutation, concurrency, cleanup, isolation, and component limits.

Fixes #6368
2026-07-23 18:58:58 +00:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
roboomp c232c3af76 fix(write): reject local read-selector-shaped write targets
A read-only step that mis-dispatches read as write passes the full read
expression (src/foo.tsx:1-260:raw) as the target. Because a literal colon
filename is legal on POSIX (#4618), write resolved it to filesystem creation
and reported success, leaving a stray zero-byte file the model could not
recover from - the local analogue of the xd:// near-miss guard (#6123).

assertNotReadSelectorMisfire now fails closed when the tail parses as a
read-tool selector, the literal target is missing, and content is empty,
pointing at the equivalent read(...). Non-empty content stays the escape
hatch and existing literal colon filenames remain writable.

Fixes #6387
2026-07-23 18:39:36 +00:00
can1357 da1056226e Merge PR #5464 port: persist vibe sessions across restarts (@roboomp) 2026-07-23 18:07:22 +02:00
can1357 5d66eb7f2a Merge PR #5464: fix(coding-agent): persist vibe sessions across restarts (@roboomp) 2026-07-23 18:06:11 +02:00
can1357 2ffb67e3c7 fix: reconciled merged tests and dead code with current main structure
- warp completion test updated to event-taking notification signature
- hindsight test config gained required timeout fields
- dropped orphaned parseBillingConfig and advisor secret-collection dupes
- deduped fixture key; formatter pass on merged files
2026-07-23 18:02:31 +02:00
pr-evalandcan1357 424458e99d chore(secrets): dropped drive-by changes unrelated to secret placeholders
Reverted branch-side edits to spawn-policy prompts/tests, settings tab
groups, mermaid cache typing, prewalk todo gating, and packages/ai test
churn back to merge-base content; trimmed their changelog entries. These
repaired stale CI against an older main and are stale or conflicting
against current main.
2026-07-23 17:56:29 +02:00
can1357 c0c1622012 Merge PR #4636: feat(secrets): add friendly names to secret placeholders (@Mathews-Tom)
# Conflicts:
#	packages/ai/test/pi-native-client.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/prompts/tools/eval.md
2026-07-23 17:56:24 +02:00
can1357 c522eceff2 Merge PR #6119: feat: lift subagent async/auto-background limits via owner-routed delivery and quiescence (@korri123)
# Conflicts:
#	packages/coding-agent/src/task/executor.ts
2026-07-23 17:52:52 +02:00
can1357 e50d67d471 chore(coding-agent): dropped drive-by prompt and spinner drift unrelated to error.notify 2026-07-23 17:49:20 +02:00
can1357 01e6ba9217 fix(bash): bound poll-tick output read and terminal release awaits 2026-07-23 17:41:55 +02:00
can1357 c507a590bf Merge PR #4270: fix(bash): bound ACP terminal lifecycle with abort/timeout (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/tools/bash.ts
#	packages/coding-agent/test/bash-acp-terminal.test.ts
2026-07-23 17:41:55 +02:00